HIGH

CVE-2023-4647

Gitlab GitLab 2023-09-01 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.

Summary dbcve.org

GitLab's projects API has a pagination bypass vulnerability in versions 15.2 through 16.3.1. Attackers can skip pagination controls to request all projects in a single large request, potentially overwhelming server resources and causing denial of service.

Mitigation

Upgrade GitLab to version 16.1.6+, 16.2.6+, 16.3.2+ or later to patch the pagination bypass. Consider rate limiting API endpoints as an additional mitigation.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.73%
Probability of exploitation in next 30 days
52.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE